CVE-2024-50972
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Nov 13, 2024
Updated: Nov 14, 2024
CWE ID 89
Summary
CVE-2024-50972 is a SQL injection vulnerability that affects the Itsourcecode Construction Management System 1.0 and its printtool.php file. This issue enables remote attackers to execute arbitrary SQL commands by exploiting the borrow_id parameter. Successful exploitation could lead to unauthorized access to sensitive data or even system takeover. It is crucial for users to apply the necessary patches or upgrades to mitigate this risk and secure their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.